Firnline

Privacy

Last updated 1 August 2026

Firnline is used by one person, to look at that person’s own bank accounts. This page describes what it does with that data.

Who is responsible

Firnline is operated by a private individual for personal, non-commercial use. Contact for data protection matters: moritz.santoni@icloud.com.

What data is accessed

Access is read-only. Firnline cannot initiate payments or modify anything at the bank.

How it is accessed

Through Enable Banking, a licensed account information service provider operating under PSD2. Authentication happens on the bank’s own pages; Firnline never sees or stores bank login credentials. Each bank connection requires explicit consent, which expires after a period set by the bank (typically 90 to 180 days) and must be renewed.

Where it is stored

On infrastructure controlled by the operator. Data is retained indefinitely, because the point of the application is a long-run financial history — banks themselves only expose a limited window.

Who it is shared with

Nobody. The data is not sold, published, shared with third parties, used for advertising or profiling, or used to train any model. The only external party in the chain is Enable Banking, which acts as the regulated intermediary to the banks and has its own privacy policy.

Legal basis

Consent (Art. 6(1)(a) GDPR), given by the account holder at each bank, and processing of the account holder’s own data for purely personal purposes.

Withdrawing consent

Bank consents can be revoked at any time — through Enable Banking’s consent portal, in the bank’s own online banking, or by emailing the address above. Revoking a consent stops further access immediately.

Your rights

As the sole user is also the operator and the data subject, the usual GDPR rights — access, rectification, erasure, portability, objection — are exercised directly. If you believe your data has somehow ended up here, write to moritz.santoni@icloud.com and it will be deleted.